2013 CVE Vulnerabilities

6,830 CVEs published in 2013.

CVE IDSeverityCVSSDescription
CVE-2013-3223The ax25_recvmsg function in net/ax25/af_ax25.c in the Linux kernel before 3.9-rc7 does not initialize a certain data st...
CVE-2013-3222The vcc_recvmsg function in net/atm/common.c in the Linux kernel before 3.9-rc7 does not initialize a certain length var...
CVE-2013-3076The crypto API in the Linux kernel through 3.9-rc8 does not initialize certain length variables, which allows local user...
CVE-2013-3221The Active Record component in Ruby on Rails 2.3.x, 3.0.x, 3.1.x, and 3.2.x does not ensure that the declared data type ...
CVE-2013-2780Siemens SIMATIC S7-1200 PLCs 2.x and 3.x allow remote attackers to cause a denial of service (defect-mode transition and...
CVE-2013-0700Siemens SIMATIC S7-1200 PLCs 2.x and 3.x allow remote attackers to cause a denial of service (defect-mode transition and...
CVE-2013-0138BitZipper 2013 before Update 1 allows remote attackers to execute arbitrary code or cause a denial of service (memory co...
CVE-2013-0122The avast! Mobile Security application before 2.0.4400 for Android allows attackers to cause a denial of service (applic...
CVE-2013-3060The web console in Apache ActiveMQ before 5.8.0 does not require authentication, which allows remote attackers to obtain...
CVE-2013-3211Unspecified vulnerability in Opera before 12.15 has unknown impact and attack vectors, related to a "moderately severe i...
CVE-2013-3210Opera before 12.15 does not properly block top-level domains in Set-Cookie headers, which allows remote attackers to obt...
CVE-2013-3075Multiple buffer overflows in ActUWzd.dll 1.0.0.1 in Mitsubishi MX Component 3, as distributed in Citect CitectFacilities...
CVE-2013-2697Cross-site request forgery (CSRF) vulnerability in the WP-DownloadManager plugin before 1.61 for WordPress allows remote...
CVE-2013-1416The prep_reprocess_req function in do_tgs_req.c in the Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) before...
CVE-2013-1086Cross-site scripting (XSS) vulnerability in WebAccess in Novell GroupWise before 8.0.3 HP3, and 2012 before SP2, allows ...
CVE-2013-0129Multiple cross-site scripting (XSS) vulnerabilities in pd-admin before 4.17 allow remote authenticated users to inject a...
CVE-2013-1199Race condition in the CIFS implementation in the rewriter module in the Clientless SSL VPN component on Cisco Adaptive S...
CVE-2013-1194The ISAKMP implementation on Cisco Adaptive Security Appliances (ASA) devices generates different responses for IKE aggr...
CVE-2013-1177SQL injection vulnerability in Cisco Network Admission Control (NAC) Manager before 4.8.3.1 and 4.9.x before 4.9.2 allow...
CVE-2013-1176The DSP card on Cisco TelePresence MCU 4500 and 4501 devices before 4.3(2.30), TelePresence MCU MSE 8510 devices before ...
CVE-2013-0139The Arecont Vision AV1355DN MegaDome camera allows remote attackers to cause a denial of service (video-capture outage) ...
CVE-2013-0133Untrusted search path vulnerability in /usr/local/psa/admin/sbin/wrapper in Parallels Plesk Panel 11.0.9 allows local us...
CVE-2013-0132The suexec implementation in Parallels Plesk Panel 11.0.9 contains a cgi-wrapper whitelist entry, which allows user-assi...
CVE-2013-1749Cross-site scripting (XSS) vulnerability in edit.php in PHP Address Book 8.2.5 allows user-assisted remote attackers to ...
CVE-2013-1748Multiple SQL injection vulnerabilities in PHP Address Book 8.2.5 allow remote attackers to execute arbitrary SQL command...

Check if your code is affected by 2013 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now